NewsCryptoThe Sandbox SAND Token Hit by Cross-Chain Exploit; Attacker Mints Billions in Unbacked Tokens

The Sandbox SAND Token Hit by Cross-Chain Exploit; Attacker Mints Billions in Unbacked Tokens

Author: Coincentral·

Key Takeaways

  • An attacker gained arbitrary minting rights on The Sandbox's SAND contract on Base and minted roughly 14.9 billion unbacked tokens, more than the token's entire 3 billion supply on Ethereum mainnet.
  • The attacker abused an "approveAndCall" function to hijack LayerZero delegate permissions, enabling minting on Base without backing from the SAND locked on Ethereum.
  • Realized losses amounted to approximately $675,000 (80 ETH) from about 14.75 million SAND drained from Ethereum, and the widely cited $49 billion figure reflects unbacked tokens valued at market price rather than stolen funds.
  • The Sandbox disabled bridging on Base and BNB Smart Chain, zeroed the LayerZero peers for Ethereum and BNB Smart Chain, and warned users not to trade SAND on the affected networks, while SAND on Ethereum and Polygon remained unaffected and no user wallets were compromised.
  • Upbit issued a trading caution for SAND and Bithumb suspended SAND deposits and withdrawals, and The Sandbox is preparing compensation for qualifying users of affected liquidity pools along with a technical post-mortem.
The Sandbox SAND Token Hit by Cross-Chain Exploit; Attacker Mints Billions in Unbacked Tokens

On August 22, 2026, an attacker gained arbitrary minting rights on The Sandbox's SAND contract deployed on Base, a LayerZero Omnichain Fungible Token (OFT) configuration used for cross-chain token movement. Under that lock-and-mint design, SAND is locked on Ethereum while an equivalent amount is minted on destination chains, so every cross-chain token is meant to be backed one-to-one. The attacker minted roughly 14.9 billion unbacked SAND tokens — a quantity that far exceeds the token's entire 3 billion supply on Ethereum mainnet — before the project halted bridging on Base and BNB Smart Chain to contain the damage. Actual losses were considerably smaller: approximately 14.75 million SAND was drained from Ethereum, netting the attacker about $675,000, or 80 ETH. SAND on Ethereum and Polygon was not affected, and no user wallets were compromised.

⚠️ALERT: Sandbox hit by a major security breach as attackers mint 49B of unbacked $SAND, compromising its ENTIRE liquidity across BSC and Base. The team has confirmed the exploit and isolated SAND liquidity on BSC and Base, while disabling bridging to and from both networks.… pic.twitter.com/UdvHTm7wuu

— Coin Bureau (@coinbureau) August 22, 2026

According to on-chain analysis, the attacker abused an "approveAndCall" function to hijack LayerZero delegate permissions. That control allowed tokens to be minted on Base without any backing from the real, locked SAND held on Ethereum. Blockchain security firm Blockaid flagged the exploit while it was still in progress. PeckShield separately confirmed that roughly 14.9 billion SAND tokens were minted across two addresses, 0xAbE0…4D22 and 0x638C…F296.

#PeckShieldAlert Seems like The @TheSandboxGame ($SAND) got exploited. 14.9B $SAND minted across 2 addresses: 0xAbE0…4D22 & 0x638C…F296 pic.twitter.com/a5Jgym87gR

— PeckShieldAlert (@PeckShieldAlert) August 22, 2026

The widely circulated headline figure of $49 billion is based on applying SAND's market price to the unbacked tokens. That number does not represent stolen funds: it far exceeds any available liquidity and cannot be realized. The direct loss was smaller. BlockWatchdog reported that approximately 14.75 million SAND was drained from the Ethereum OFT Adapter in under a minute, with realized proceeds of around 80 ETH, worth roughly $675,000. The Sandbox said the exploit affected less than 0.01% of SAND's 3 billion token supply when measured directly.

How The Sandbox Responded

The project disabled bridging to and from Base and BNB Smart Chain, leaving tokens on those networks unable to move or be redeemed. The project's multisig also zeroed the LayerZero peers for Ethereum and BNB Smart Chain, effectively isolating Base. The team warned users not to buy, sell, or trade SAND on Base or BNB due to compromised liquidity. SAND on Ethereum and Polygon was confirmed unaffected, and the SAND locked on Ethereum to back cross-chain tokens remained intact.

South Korean exchanges moved quickly after on-chain alerts flagged the breach. Upbit issued a trading caution for SAND, while Bithumb suspended SAND deposits and withdrawals.

The Sandbox, an Animoca Brands subsidiary that raised $93 million in 2021, is a user-generated gaming metaverse where players build and monetize voxel-based experiences, with SAND serving as its ERC-20 utility token for in-world transactions, LAND parcel purchases, staking, and governance votes. The company said it is taking a snapshot from before the incident and preparing compensation for qualifying users of affected liquidity pools. A technical post-mortem is planned. At the time of writing, the team had not issued a full public statement on the root cause of the exploit.

SAND dropped nearly 10% intraday following the incident but was down just 0.8% over the 24-hour period.

The exploit highlights a known structural risk in cross-chain token deployments. Minting tokens on a secondary chain does not create new supply on Ethereum, but unbacked tokens can still reach exchanges and pressure prices. Bridge and cross-chain infrastructure has produced some of the largest losses in crypto security history — the Ronin Bridge theft of roughly $600 million and the Wormhole exploit of about $320 million, both in 2022, rank among the biggest on record — though the realized proceeds here, about $675,000, are a small fraction of those totals. Pending items include updates from Upbit and Bithumb on the resumption of SAND trading, and The Sandbox's official recovery or burn plan.

Source: CoinCentral